01 / 10  ·  Overview
OPEN PROTOCOL

Governance
infrastructure for
the agent economy.

Authority before action. Receipts after.

View the protocol → Read the spec Contact →
OPEN PROTOCOL

Governance infrastructure for the agent economy.

Authority before action. Receipts after.

View the protocol → Read the spec Contact →
01 / 10
PRINCIPLE
Signed agreement Verified receipt

The world runs
on receipts.

Receipts turn actions into evidence.

Agent actions
need the same.

Every consequential agent action should leave one.

SIGNED / TAMPER-EVIDENT / VERIFIABLE OUTSIDE THE VENDOR
PRINCIPLE

The world runs on receipts.

Receipts turn actions into evidence.

Signed agreement Verified receipt

Agent actions need the same.

Every consequential agent action should leave one.

SIGNED / TAMPER-EVIDENT / VERIFIABLE OUTSIDE THE VENDOR
02 / 10
PROBLEM

Access is not authority.

Agents can act for people and companies. Nothing
proves the basics.

01
Who authorized it
identity + principal
02
What it was allowed to do
scope + conditions
03
What actually happened
evidence + receipt

API keys grant access. Logs are
written by the party being audited.

PROBLEM

Access is not authority.

Agents can act for people and companies. Nothing proves the basics.

01
Who authorized it
identity + principal
02
What it was allowed to do
scope + conditions
03
What actually happened
evidence + receipt

API keys grant access. Logs are written by the party being audited.

03 / 10
WHY NOW

Agents now take
actions companies
must answer for.

CHAT
ACTION
TOUCHES
Money
spend / approvals
Customer data
access / handling
Regulated workflows
records / audit
External APIs
real-world effects

The moment an agent acts, you need proof of
authority, not logs after the fact.

WHY NOW

Agents now take actions companies must answer for.

CHAT
ACTION
TOUCHES
Money
spend / approvals
Customer data
access / handling
Regulated workflows
records / audit
External APIs
real-world effects

The moment an agent acts, you need proof of authority, not logs after the fact.

04 / 10
SOLUTION

Agent Passport System (APS)

A tamper-evident trail from authority to action.

01
Verifiable identity
who the agent represents
02
Scoped authority
what it can do, how long, how much
03
Gateway enforcement
policy checked at execution
04
Signed receipts
proof of permitted and denied actions
SOLUTION

Agent Passport System (APS)

A tamper-evident trail from authority to action.

01
Verifiable identity
who the agent represents
02
Scoped authority
what it can do, how long, how much
03
Gateway enforcement
policy checked at execution
04
Signed receipts
proof of permitted and denied actions
05 / 10
PRODUCT MECHANICS

THE GATEWAY CHECKS AUTHORITY BEFORE EXECUTION.

DELEGATED SCOPE CAN ONLYNARROW.
CLIENT / AGENT REQUEST
A declared action arrives with
the authority behind it.
01 IDENTITYpassport or enterprise identity
02 DELEGATION CHAINoriginal delegation through
every sub-agent
03 ACTIONtarget, scope, limits
APS GATEWAY
authority checkpoint before the enterprise API
DECLARED
ACTION
SCOPE · BUDGET · RIGHTS · POLICIES
PERMIT
ENTERPRISE API
The action executes.
DENY
STOP BEFORE API
The action never dispatches.
PORTABLE EVIDENCE
signed action receipt  /  signed denial record
for the company, customer, or auditor
ENFORCED BY ARCHITECTURE,NOT TRUST.
PRODUCT MECHANICS

THE GATEWAY CHECKS AUTHORITY BEFORE EXECUTION.

DELEGATED SCOPE CAN ONLY NARROW.
CLIENT / AGENT REQUEST
A declared action arrives with the authority behind it.
01IDENTITYpassport or enterprise identity
02DELEGATION CHAINoriginal delegation through every sub-agent
03ACTIONtarget, scope, limits
APS GATEWAY
authority checkpoint before the enterprise API
DECLARED ACTION
SCOPE · BUDGET · RIGHTS · POLICIES
PERMIT
ENTERPRISE API
The action executes.
DENY
STOP BEFORE API
The action never dispatches.
PORTABLE EVIDENCE
signed action receipt / signed denial record
for the company, customer, or auditor
ENFORCED BY ARCHITECTURE, NOT TRUST.
06 / 10
CATEGORY

The vendor can't
grade its own
homework.

Enterprise APIs
Stripe · Salesforce
APS
neutral enforcement layer
Model vendors
OpenAI · Anthropic

Works above payment and
model rails. Proof before
the action, evidence after.

CATEGORY

The vendor can't grade its own homework.

Enterprise APIs
Stripe · Salesforce
APS
neutral enforcement layer
Model vendors
OpenAI · Anthropic

Works above payment and model rails. Proof before the action, evidence after.

07 / 10
LANDSCAPE

A crowded stack. One layer still open.

IdentityEntra Agent ID · Google Agent Identity · AWS AgentCore Identity · Okta · Auth0
Runtime access & enforcementPing Agent Gateway · Okta Agent Gateway · Google Agent Gateway · AWS AgentCore Gateway
Agent trust & discoveryERC-8004 · A2A Agent Cards
Authorization & delegationOpenID AuthZEN · OAuth agent delegation · Cedar
Verifiable action authority, attribution & evidenceAPS

Identity says who the agent is. APS governs
the action and records the decision.

LANDSCAPE

A crowded stack. One layer still open.

Identity
Entra Agent ID · Google Agent Identity · AWS AgentCore Identity · Okta · Auth0
Runtime access & enforcement
Ping Agent Gateway · Okta Agent Gateway · Google Agent Gateway · AWS AgentCore Gateway
Agent trust & discovery
ERC-8004 · A2A Agent Cards
Authorization & delegation
OpenID AuthZEN · OAuth agent delegation · Cedar
Verifiable action authority, attribution & evidence
APS

Identity says who the agent is. APS governs the action and records the decision.

08 / 10
VISION

People participate in the agent economy.
They are not subsidized by it.

Every outcome an agent produces creates value, damage, or both. APS keeps each one attributable to a principal.

AGENT OUTCOME
PRINCIPAL
WHO AUTHORIZED
VALUE CREATED
BENEFICIARY
credit · ownership · payment
DAMAGE CAUSED
AFFECTED PARTY
accountability · cost · loss
NEXT: DATA AND COMMERCE ATTRIBUTION

Whose data was used. Who gets credited. Who gets paid.

VISION

People participate in the agent economy. They are not subsidized by it.

Every outcome an agent produces creates value, damage, or both. APS keeps each one attributable to a principal.

AGENT OUTCOME
PRINCIPAL
WHO AUTHORIZED
VALUE CREATED
BENEFICIARY
credit · ownership · payment
DAMAGE CAUSED
AFFECTED PARTY
accountability · cost · loss
NEXT: DATA AND COMMERCE ATTRIBUTION

Whose data was used. Who gets credited. Who gets paid.

09 / 10
CLOSE

The web needed TLS
for trust in transit.

Card payments needed PCI
for accountable handling.

Agent actions need their
own accountability layer.

Get in touch → View on GitHub
Building it, in the open.
CLOSE

The web needed TLS for trust in transit.

Card payments needed PCI for accountable handling.

Agent actions need their own accountability layer.

Get in touch → View on GitHub
Building it, in the open.
10 / 10